WriteConsoleW
|
buffer:
Directory: C:\ProgramData
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Mode LastWriteTime Length Name
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
d---- 2023-02-28 오전 9:49 MEMEMAN
console_handle:
0x00000037
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
The term '£££' is not recognized as the name of a cmdlet, function, script file
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
, or operable program. Check the spelling of the name, or if a path was include
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
d, verify that the path is correct and try again.
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:5 char:5
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ (£££ <<<< (£££(£££ $AMI))) | .('{x}{9}'.replace('9','0').replace('x','1')-f'
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Pussy','%%').replace('%%','I').replace('Pussy','EX')
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : ObjectNotFound: (£££:String) [], CommandNotFound
console_handle:
0x0000006b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Exception
console_handle:
0x00000077
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : CommandNotFoundException
console_handle:
0x00000083
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
You cannot call a method on a null-valued expression.
console_handle:
0x00000023
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:15 char:18
console_handle:
0x0000002f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $o = $h.GetMethod <<<< ($k)
console_handle:
0x0000003b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (GetMethod:String) [], Runtime
console_handle:
0x00000047
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
Exception
console_handle:
0x00000053
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : InvokeMethodOnNull
console_handle:
0x0000005f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
You cannot call a method on a null-valued expression.
console_handle:
0x0000007f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:22 char:10
console_handle:
0x0000008b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $o.Invoke <<<< ($hh, ($V4,$Ripple))
console_handle:
0x00000097
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (Invoke:String) [], RuntimeExc
console_handle:
0x000000a3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eption
console_handle:
0x000000af
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : InvokeMethodOnNull
console_handle:
0x000000bb
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
You cannot call a method on a null-valued expression.
console_handle:
0x000000db
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:23 char:10
console_handle:
0x000000e7
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $o.Invoke <<<< ($hh, ($V2,$Ripple))
console_handle:
0x000000f3
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (Invoke:String) [], RuntimeExc
console_handle:
0x000000ff
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eption
console_handle:
0x0000010b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : InvokeMethodOnNull
console_handle:
0x00000117
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
You cannot call a method on a null-valued expression.
console_handle:
0x00000137
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
At line:24 char:10
console_handle:
0x00000143
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ $o.Invoke <<<< ($hh, ($V3,$Ripple))
console_handle:
0x0000014f
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ CategoryInfo : InvalidOperation: (Invoke:String) [], RuntimeExc
console_handle:
0x0000015b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
eption
console_handle:
0x00000167
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
+ FullyQualifiedErrorId : InvokeMethodOnNull
console_handle:
0x00000173
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
VERBOSE: Performing operation "Copy File" on Target "Item:
C:\ProgramData\MEMEMAN\CypherDeptography.~+~ Destination:
C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\CypherDeptography.~+~".
console_handle:
0x0000001b
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
VERBOSE: Performing operation "Copy File" on Target "Item:
C:\ProgramData\MEMEMAN\UpdateEscan.js Destination:
C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\UpdateEscan.js".
console_handle:
0x00000027
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
VERBOSE: Performing operation "Copy File" on Target "Item:
C:\ProgramData\MEMEMAN\WindowsDEFENDERUPDATE.js Destination:
C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start
Menu\Programs\Startup\WindowsDEFENDERUPDATE.js".
console_handle:
0x00000033
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
SUCCESS: The scheduled task "EscansUpdate" has successfully been created.
console_handle:
0x00000007
|
1
|
1 |
0
|
WriteConsoleW
|
buffer:
SUCCESS: The scheduled task "EscanDissldo" has successfully been created.
console_handle:
0x00000007
|
1
|
1 |
0
|